{"id":"MAL-2026-2945","title":"Malicious code in moonbit-locale-compat (PyPI)","summary":"Malicious code in moonbit-locale-compat (PyPI)","severity":"none","vendor":"moonbit-locale-compat","product":"moonbit-locale-compat","ecosystem":"pip","affected":["moonbit-locale-compat"],"published":"2026-04-20","updated":"2026-07-09","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-2945","references":[{"url":"https://github.com/zongen01/wechat-editor-studio/pull/2/changes#diff-d9555f91ec2cf16d2b3d23115fe3cf6600fa8b42627de82a81da48191c54d99c"},{"url":"https://bad-packages.kam193.eu/pypi/package/moonbit-locale-compat"},{"url":"https://github.com/DiamondFrontline/wechat-editor-studio/commit/3c61484843fbc7fbeb5e81149296aa7843570ee1"}],"tags":["osv","pip"],"ingestedAt":"2026-07-09T11:56:19.139Z","slug":"MAL-2026-2945","body":"## Overview\n\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: kam193 (d42bb32adb1fb5f388368b9e4ab382bfbc8cd7f62dab4c70a8563a448ce9c2af)\nCampaign includes a chain of dependencies that finally exfiltrate sensitive environment variables to a hardcoded GitHub repository as exfiltration target, and in specific environments also start a reverse shell. It appears to be targeting specifically one GitHub project, where the front-end package was included in a PR.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-04-moonbit-locale-compat\n\n\nReasons (based on the campaign):\n\n\n - The malicious code is intentionally included in a dependency of the package\n\n\n - The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine.\n\n\n - exfiltration-env-variables\n\n\n## Affected packages\n\n- `moonbit-locale-compat`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}